{
    "document": {
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "nl",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions:\n\n    NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein.\n\n    NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory.\n    This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            },
            {
                "category": "description",
                "text": "Google heeft kwetsbaarheden verholpen in Android.\n\nSamsung heeft de voor Samsung Mobile relevante kwetsbaarheden verholpen in hun producten.",
                "title": "Feiten"
            },
            {
                "category": "description",
                "text": "De kwetsbaarheden betreffen onder andere onjuiste bounds checking, ontbrekende permissiecontroles, integer overflows, onjuist geïnitialiseerde pointers, type confusion, race conditions en onjuiste exception handling.\n\nDeze fouten kunnen leiden tot out-of-bounds memory reads en writes, geheugen corruptie, privilege escalatie, informatielekken, denial-of-service situaties en controle over het systeem door een aanvaller. Exploitatie kan lokaal of op afstand plaatsvinden, vaak zonder dat er gebruikersinteractie of verhoogde rechten nodig zijn.\n\nDe kwetsbaarheden zijn aanwezig in diverse functies en modules die gebruikt worden in verschillende softwareomgevingen, waaronder Bluetooth subsystemen, netwerk parsing, device management en audio controllers.",
                "title": "Interpretaties"
            },
            {
                "category": "description",
                "text": "Google heeft updates uitgebracht om de kwetsbaarheden te verhelpen in Android 14, 15, 16 en 17.\n\nSamsung heeft updates uitgebracht om de voor Samsung relevante kwetsbaarheden te verhelpen in Samsung Mobile devices.\n\nZie bijgevoegde referenties voor meer informatie.",
                "title": "Oplossingen"
            },
            {
                "category": "general",
                "text": "medium",
                "title": "Kans"
            },
            {
                "category": "general",
                "text": "high",
                "title": "Schade"
            },
            {
                "category": "general",
                "text": "Heap-based Buffer Overflow",
                "title": "CWE-122"
            },
            {
                "category": "general",
                "text": "Integer Overflow or Wraparound",
                "title": "CWE-190"
            },
            {
                "category": "general",
                "text": "Uncaught Exception",
                "title": "CWE-248"
            },
            {
                "category": "general",
                "text": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
                "title": "CWE-362"
            },
            {
                "category": "general",
                "text": "Unintended Proxy or Intermediary ('Confused Deputy')",
                "title": "CWE-441"
            },
            {
                "category": "general",
                "text": "Use of Uninitialized Variable",
                "title": "CWE-457"
            },
            {
                "category": "general",
                "text": "Out-of-bounds Write",
                "title": "CWE-787"
            },
            {
                "category": "general",
                "text": "Access of Uninitialized Pointer",
                "title": "CWE-824"
            },
            {
                "category": "general",
                "text": "Access of Resource Using Incompatible Type ('Type Confusion')",
                "title": "CWE-843"
            },
            {
                "category": "general",
                "text": "Missing Authorization",
                "title": "CWE-862"
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "Nationaal Cyber Security Centrum",
            "namespace": "https://www.ncsc.nl/"
        },
        "references": [
            {
                "category": "external",
                "summary": "Reference",
                "url": "https://security.samsungmobile.com/securityUpdate.smsb"
            },
            {
                "category": "external",
                "summary": "Reference",
                "url": "https://source.android.com/docs/security/bulletin/2026/2026-10-01"
            }
        ],
        "title": "Kwetsbaarheden verholpen in Google Android",
        "tracking": {
            "current_release_date": "2026-10-07T15:21:06.565619Z",
            "generator": {
                "date": "2025-08-04T16:30:00Z",
                "engine": {
                    "name": "V.A.",
                    "version": "1.3"
                }
            },
            "id": "NCSC-2026-0405",
            "initial_release_date": "2026-10-07T15:21:06.565619Z",
            "revision_history": [
                {
                    "date": "2026-10-07T15:21:06.565619Z",
                    "number": "1.0.0",
                    "summary": "Initiele versie"
                }
            ],
            "status": "final",
            "version": "1.0.0"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-1"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Android"
                    }
                ],
                "category": "vendor",
                "name": "Google"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-2"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Samsung Mobile"
                    }
                ],
                "category": "vendor",
                "name": "Samsung"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-21114",
            "notes": [
                {
                    "category": "description",
                    "text": "An out-of-bounds write vulnerability in libsmkvextractor.so prior to SMR Oct-2026 Release 1 allows local attackers to execute arbitrary code.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-21114 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-21114.json"
                }
            ],
            "title": "CVE-2026-21114"
        },
        {
            "cve": "CVE-2026-21115",
            "notes": [
                {
                    "category": "description",
                    "text": "A local vulnerability in libcodec2-sec-flacdec.so prior to SMR Oct-2026 Release 1 allows out-of-bounds memory writes, potentially compromising system integrity.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-21115 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-21115.json"
                }
            ],
            "title": "CVE-2026-21115"
        },
        {
            "cve": "CVE-2026-21116",
            "notes": [
                {
                    "category": "description",
                    "text": "A local vulnerability in libsmkvextractor.so prior to SMR Oct-2026 Release 1 enables attackers to execute out-of-bounds memory writes, potentially compromising system integrity.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-21116 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-21116.json"
                }
            ],
            "title": "CVE-2026-21116"
        },
        {
            "cve": "CVE-2026-21117",
            "notes": [
                {
                    "category": "description",
                    "text": "An improper access control vulnerability in CocktailBarService prior to SMR Oct-2026 Release 1 allows local attackers to gain unauthorized access to sensitive information.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-21117 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-21117.json"
                }
            ],
            "title": "CVE-2026-21117"
        },
        {
            "cve": "CVE-2026-21118",
            "notes": [
                {
                    "category": "description",
                    "text": "An improper access control vulnerability in DownloadProvider before SMR Oct-2026 Release 1 allows local attackers to access files within scoped storage, potentially exposing sensitive data.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-21118 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-21118.json"
                }
            ],
            "title": "CVE-2026-21118"
        },
        {
            "cve": "CVE-2026-21119",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in lib_sag_ai_sound_sep_v2.00.so prior to SMR Oct-2026 Release 1 permits local attackers to execute out-of-bounds memory read and write operations, potentially compromising system integrity.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-21119 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-21119.json"
                }
            ],
            "title": "CVE-2026-21119"
        },
        {
            "cve": "CVE-2026-21120",
            "notes": [
                {
                    "category": "description",
                    "text": "A use-after-free vulnerability in the WSM service prior to the SMR Oct-2026 Release 1 allows local attackers to execute arbitrary code with system-level privileges.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-21120 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-21120.json"
                }
            ],
            "title": "CVE-2026-21120"
        },
        {
            "cve": "CVE-2026-21121",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in CmcCore before SMR Oct-2026 Release 1 allows local attackers to exploit privileged APIs due to improper handling of insufficient permissions, leading to potential unauthorized access.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-21121 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-21121.json"
                }
            ],
            "title": "CVE-2026-21121"
        },
        {
            "cve": "CVE-2026-21122",
            "notes": [
                {
                    "category": "description",
                    "text": "A local vulnerability in libsamsungtts.so prior to SMR Oct-2026 Release 1 enables arbitrary code execution through an out-of-bounds write.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-21122 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-21122.json"
                }
            ],
            "title": "CVE-2026-21122"
        },
        {
            "cve": "CVE-2026-21123",
            "notes": [
                {
                    "category": "description",
                    "text": "An improper privilege management vulnerability in Locksettings before SMR Oct-2026 Release 1 allows local attackers with root access to access data from the tied profile prior to the device's first unlock.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-21123 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-21123.json"
                }
            ],
            "title": "CVE-2026-21123"
        },
        {
            "cve": "CVE-2026-21124",
            "notes": [
                {
                    "category": "description",
                    "text": "A local code execution vulnerability exists in Samsung's libsimba.heifdec.media.samsung.so prior to SMR Oct-2026 Release 1 due to improper input validation when processing cover images.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-21124 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-21124.json"
                }
            ],
            "title": "CVE-2026-21124"
        },
        {
            "cve": "CVE-2026-21125",
            "notes": [
                {
                    "category": "description",
                    "text": "A local code execution vulnerability exists in Samsung's libsimba.heifdec.media.samsung.so prior to SMR Oct-2026 Release 1 due to improper input validation during parsing of sheifd data.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-21125 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-21125.json"
                }
            ],
            "title": "CVE-2026-21125"
        },
        {
            "cve": "CVE-2026-21126",
            "notes": [
                {
                    "category": "description",
                    "text": "A local vulnerability in Samsung's libsimba.heifdec.media.samsung.so prior to SMR Oct-2026 Release 1 allows out-of-bounds memory writes due to improper input validation when retrieving cover images.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-21126 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-21126.json"
                }
            ],
            "title": "CVE-2026-21126"
        },
        {
            "cve": "CVE-2026-28667",
            "notes": [
                {
                    "category": "description",
                    "text": "Multiple functions in rw_t5t.cc lack proper bounds checking, leading to potential out-of-bounds reads that could cause local information disclosure without requiring additional privileges or user interaction.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-28667 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-28667.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "baseScore": 5.5,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-28667"
        },
        {
            "cve": "CVE-2026-45513",
            "notes": [
                {
                    "category": "description",
                    "text": "Elevation of privilege is a security vulnerability that allows attackers to gain unauthorized access to higher system permissions, potentially compromising system integrity and security controls.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-45513 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-45513.json"
                }
            ],
            "title": "CVE-2026-45513"
        },
        {
            "cve": "CVE-2026-45516",
            "notes": [
                {
                    "category": "description",
                    "text": "The document addresses the concept of information disclosure, focusing on the exposure of sensitive data through various means.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-45516 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-45516.json"
                }
            ],
            "title": "CVE-2026-45516"
        },
        {
            "cve": "CVE-2026-45524",
            "cwe": {
                "id": "CWE-862",
                "name": "Missing Authorization"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Missing Authorization",
                    "title": "CWE-862"
                },
                {
                    "category": "description",
                    "text": "A missing permission check in WifiPermissionsUtil.java's isSystem function enables sandbox escape, resulting in local privilege escalation without user interaction or additional execution privileges.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-45524 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-45524.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-45524"
        },
        {
            "cve": "CVE-2026-49878",
            "cwe": {
                "id": "CWE-787",
                "name": "Out-of-bounds Write"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Out-of-bounds Write",
                    "title": "CWE-787"
                },
                {
                    "category": "description",
                    "text": "A logic error in the wpas_handle_robust_av_scs_recv_action function of robust_av.c can lead to an out-of-bounds write, enabling remote code execution with System privileges without user interaction.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-49878 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-49878.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-49878"
        },
        {
            "cve": "CVE-2026-49880",
            "notes": [
                {
                    "category": "description",
                    "text": "A missing bounds check in multiple functions of nfa_nfcee_act.cc can lead to out-of-bounds writes, enabling local privilege escalation without additional execution privileges or user interaction.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-49880 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-49880.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-49880"
        },
        {
            "cve": "CVE-2026-49885",
            "cwe": {
                "id": "CWE-190",
                "name": "Integer Overflow or Wraparound"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Integer Overflow or Wraparound",
                    "title": "CWE-190"
                },
                {
                    "category": "description",
                    "text": "An integer overflow in rw_t4t_update_file of rw_t4t.cc can cause an out-of-bounds write, enabling local privilege escalation without requiring additional execution privileges or user interaction.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-49885 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-49885.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-49885"
        },
        {
            "cve": "CVE-2026-49933",
            "cwe": {
                "id": "CWE-824",
                "name": "Access of Uninitialized Pointer"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Access of Uninitialized Pointer",
                    "title": "CWE-824"
                },
                {
                    "category": "description",
                    "text": "A control-flow hijack vulnerability in the privileged Bluetooth process's handle_le_monitor_device_event function due to an uninitialized pointer dereference allows local privilege escalation without user interaction or extra execution privileges.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-49933 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-49933.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-49933"
        },
        {
            "cve": "CVE-2026-49937",
            "notes": [
                {
                    "category": "description",
                    "text": "Multiple functions in MessageQueueBase.h contain incorrect bounds checks leading to potential out-of-bounds reads that may enable local privilege escalation without additional execution privileges or user interaction.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-49937 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-49937.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-49937"
        },
        {
            "cve": "CVE-2026-55265",
            "notes": [
                {
                    "category": "description",
                    "text": "PduParser.java contains multiple functions lacking bounds checks, leading to potential out-of-bounds reads that could enable remote denial of service without user interaction or elevated privileges.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-55265 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-55265.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-55265"
        },
        {
            "cve": "CVE-2026-55266",
            "notes": [
                {
                    "category": "description",
                    "text": "A resource exhaustion issue in libufdt_sysdeps_vendor.c's qsort function may cause an out-of-bounds write, enabling local privilege escalation without additional execution privileges or user interaction.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-55266 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-55266.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-55266"
        },
        {
            "cve": "CVE-2026-55269",
            "notes": [
                {
                    "category": "description",
                    "text": "A local privilege escalation vulnerability exists in the FilterCapturedPacket function of snoop_logger.cc, allowing escalation without additional execution privileges or user interaction.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-55269 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-55269.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-55269"
        },
        {
            "cve": "CVE-2026-55270",
            "cwe": {
                "id": "CWE-441",
                "name": "Unintended Proxy or Intermediary ('Confused Deputy')"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Unintended Proxy or Intermediary ('Confused Deputy')",
                    "title": "CWE-441"
                },
                {
                    "category": "description",
                    "text": "A permission bypass vulnerability in the dialInternal function can enable local privilege escalation without requiring additional execution privileges or user interaction.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-55270 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-55270.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-55270"
        },
        {
            "cve": "CVE-2026-55279",
            "notes": [
                {
                    "category": "description",
                    "text": "Denial-of-Service (DoS) attacks aim to disrupt network services by overwhelming them with excessive traffic or requests, rendering them unavailable to legitimate users.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-55279 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-55279.json"
                }
            ],
            "title": "CVE-2026-55279"
        },
        {
            "cve": "CVE-2026-55280",
            "cwe": {
                "id": "CWE-457",
                "name": "Use of Uninitialized Variable"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Use of Uninitialized Variable",
                    "title": "CWE-457"
                },
                {
                    "category": "description",
                    "text": "A vulnerability involving potential out-of-bounds writes from uninitialized data may enable remote privilege escalation without requiring user interaction or additional execution privileges.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-55280 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-55280.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-55280"
        },
        {
            "cve": "CVE-2026-55286",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in stpropnci_process of stpropnci.cc allows an out-of-bounds write due to improper bounds checking, potentially enabling local privilege escalation without user interaction or additional execution privileges.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-55286 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-55286.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-55286"
        },
        {
            "cve": "CVE-2026-58815",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability due to incorrect bounds checks in multiple locations can enable local privilege escalation without requiring additional execution privileges or user interaction.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-58815 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-58815.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-58815"
        },
        {
            "cve": "CVE-2026-58834",
            "notes": [
                {
                    "category": "description",
                    "text": "An input validation flaw in setPermissionGrantState of DevicePolicyManagerService.java can lead to a persistent local denial of service without user interaction or elevated privileges.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-58834 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-58834.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "baseScore": 5.5,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-58834"
        },
        {
            "cve": "CVE-2026-58835",
            "cwe": {
                "id": "CWE-122",
                "name": "Heap-based Buffer Overflow"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Heap-based Buffer Overflow",
                    "title": "CWE-122"
                },
                {
                    "category": "description",
                    "text": "A heap buffer overflow vulnerability in the cfg2prop function of btif_storage.cc can lead to an out-of-bounds write, potentially enabling remote code execution without additional privileges or user interaction.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-58835 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-58835.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-58835"
        },
        {
            "cve": "CVE-2026-58841",
            "notes": [
                {
                    "category": "description",
                    "text": "A logic error in multiple functions of VirtualAudioControllerTest.java enables a permission bypass, resulting in local privilege escalation without requiring additional execution privileges or user interaction.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-58841 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-58841.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-58841"
        },
        {
            "cve": "CVE-2026-58854",
            "cwe": {
                "id": "CWE-843",
                "name": "Access of Resource Using Incompatible Type ('Type Confusion')"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Access of Resource Using Incompatible Type ('Type Confusion')",
                    "title": "CWE-843"
                },
                {
                    "category": "description",
                    "text": "A type confusion vulnerability in multiple locations can lead to memory corruption, enabling local privilege escalation without requiring additional execution privileges or user interaction.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-58854 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-58854.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-58854"
        },
        {
            "cve": "CVE-2026-58856",
            "notes": [
                {
                    "category": "description",
                    "text": "A missing bounds check in DeprecatedCamera3StreamSplitter.cpp's returnOutputBufferLocked function can cause an out-of-bounds read, potentially leading to local information disclosure without user interaction or additional privileges.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-58856 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-58856.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "baseScore": 3.3,
                        "baseSeverity": "LOW"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-58856"
        },
        {
            "cve": "CVE-2026-58859",
            "cwe": {
                "id": "CWE-248",
                "name": "Uncaught Exception"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Uncaught Exception",
                    "title": "CWE-248"
                },
                {
                    "category": "description",
                    "text": "The document details a denial of service vulnerability stemming from uncaught exceptions that may enable local privilege escalation without user interaction or additional execution privileges.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-58859 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-58859.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-58859"
        },
        {
            "cve": "CVE-2026-58865",
            "notes": [
                {
                    "category": "description",
                    "text": "PduParser.java contains multiple functions lacking bounds checks, potentially enabling remote persistent denial of service attacks without user interaction or elevated privileges.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-58865 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-58865.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-58865"
        },
        {
            "cve": "CVE-2026-58880",
            "cwe": {
                "id": "CWE-362",
                "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
                    "title": "CWE-362"
                },
                {
                    "category": "description",
                    "text": "A race condition in the handle_app_val_response function of btif_rc.cc can lead to local privilege escalation without requiring additional execution privileges or user interaction.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-58880 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-58880.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2"
                    ]
                }
            ],
            "title": "CVE-2026-58880"
        }
    ]
}